SAP Security Note
High priority
SAP security note 1592567, "Directory Traversal in SPED-EFD", is a program error note released on 13.09.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential Directory Traversal in SPED-EFD.
Solution
Please refer to Note 1497003 for additional information and instructions. The corrections from Note 1497003 are a prerequisite for the implementation of this note.
Logical File Name Used in this Solution: FILE_EFD_SPED
Program Using this Logical Filename: J_1BEFD_MAIN
Logical File Path Used in this Solution: FILE_EFD_SPED
Reason and prerequisites
- The program contained in the correction instructions contains vulnerabilities through which a malicious user can potentially read arbitrary files on the remote server, possibly disclosing confidential information.
- The program contained in the correction instructions contains a vulnerability through which a malicious user can potentially write arbitrary files on the remote server, possibly corrupting data or altering system behavior.
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1592567
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
